Cloud Should Be Part Of BC/DR Plans

It's 3:30 a.m. in a raging supercell thunderstorm. Do you know where your disaster recovery plan is? How about your backup data, redundant servers, and off-site facility? Can you spin up mission-critical business applications?

And no, two out of three isn't good enough.

Everyone pays lip service to the importance of resiliency, but CIOs have a lot of priorities, with more added every day: figure out whether software-defined networking is a fit, how much of the IT budget the CMO now controls, and how the heck DevOps would ever work here. Spending hundreds of staff hours and seven figures to mitigate a 1%, or even 10%, risk scenario — and then keeping that plan current in today's level of technology churn — doesn't seem like a great return on investment when you're struggling to meet new service requests. As a result, just 41% of respondents to our InformationWeek 2014 State of Enterprise Storage Survey say they have a disaster recovery and business continuity plan and test it regularly.

But what if you could shift the cost equation of disaster recovery one decimal point to the left by being open to a new way of doing business?

Cloud-based disaster recovery services combine public cloud infrastructure and SaaS automation software to make implementing world-class continuity easier than it's ever been. Today's disaster-recovery-as-a-service market includes big IaaS shops such as Amazon Web Services and IBM as well as specialists including PHD Virtual and Zerto. For data transport between on-premises and cloud-hosted systems, IT can take advantage of enterprise-class cloud backup and replication software from firms like Asigra, CommVault, and TwinStrata. Cloud providers maintain geographically distributed datacenter facilities with state-of-the-art uptime and security.

If you tier your data and prioritize services and applications, you can take advantage of granular subscription models that reflect a wide range of cost, performance, availability, recovery time and recovery point objectives, and redundancy options.

When does a DRaaS offering reach the level of enterprise class? It needs to go beyond the basic cloud-based backup services we profile in our InformationWeek Cloud Storage, Backup and Synchronization Buyer's Guide to include a full panoply of application encapsulation, data replication, failover/failback automation, and testing services that deliver familiar IT runbook processes in a service model.

Backup is purely about data protection, while disaster recovery is restoration of the entire application infrastructure at another facility, explains Network Computing contributor David Hill. Business continuity is about both operational recovery and disaster recovery. "Operational recovery pertains to recovery from a specific problem at a primary site, such as a server, application, or disk failure," writes Hill. Cloud DR and BC services bundle three elements: off-site data protection, automated infrastructure and application recovery, and, in the case of DR, cloud-hosted virtual infrastructure.

From IT's perspective, automating the disaster recovery process and turning it into a service simplifies testing and validation and allows for easier setup of multiple failover snapshots for different system and application configurations. Furthermore, moving DR to the cloud means there's no redundant infrastructure that you build and maintain but that sits idle most of the time, and few software images to keep patched and updated.

The existing approach doesn't inspire great confidence. Our 2013 Backup Technologies Survey shows 66% still backing up directly to tape and just 27% extremely confident in their ability to get the business up and running again in a reasonable time frame after a major disaster takes out the main datacenter. Scary, but likely accurate given the pace of new applications coming online.

Cloud makes the DR scenario less complicated and highly reproducible. So why isn't everyone buying in? One reason is that the total cost of cloud DR isn't always clear cut, and another is that familiar cloud concerns around performance and security hold some back.

Moreover, the stumbling block to quick business recovery is usually not data, it's applications. In fact, one bright spot is that most enterprises are quite rigorous about retaining data. Our backup technologies survey found 71% of respondents clone 90% or more of their physical systems weekly.

Recovering applications is where the breakdown occurs. Eleven percent of backup respondents haven't tested the restore process for some or all of their applications, while 45% do so haphazardly.

Our advice for the cloud-wary is to look at adopting DRaaS as a three-step process: Get some cloud storage, then backup, then go all in on disaster recovery.

Kurt Marko is an InformationWeek and Network Computing contributor and IT industry veteran, pursuing his passion for communications after a varied career that has spanned virtually the entire high-tech food chain from chips to systems. Upon graduating from Stanford University ... View Full Bio

We welcome your comments on this topic on our social media channels, or [contact us directly] with questions about the site.

Good analysis, Kurt, and I agree with your recommended, how to get started list. The day is not far off when not having DR in the cloud will be as damning as not having firewalls in the data center. The cloud offers not only a reasonably low cost DR process but an alternative site strategy, rolled into one. Should be a no-brainer.

Great article on how cloud DR is going to be a critical service moving forward. To add to this, the real complication will come from network recovery. Right now I am not surprised to see such a high number of users backup to tape, since it's cost-effective and relatively quick. The problem with cloud DR is that if you need to backup from a cloud site, the network usage is the real wild card. On one hand, the amount of data that might be affected could mean a huge network bill if you are consistently replicating and need to do a backup. A lot of service providers forget to mention this little detail. a few terabytes could be not just a nightmare from a cost perspective, but the time it would take could be the lead contributor to your downtime. The other option is to look at DR providers who leverage WAN optimization to help streamline the process and prioritize packets in order to make these services more nimble, since the faster you can regain your data, the less damage the outage will do to your organization.

Transformation is on every IT organization's to-do list, but effectively transforming IT means a major shift in technology as well as business models and culture. In this IT Trend Report, we examine some of the misconceptions of digital transformation and look at steps you can take to succeed technically and culturally.